Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
100

SUSE Linux Micro 6.0 krb5 Moderate Checksum Issue Advisory 2025-20314-1

An update that solves one vulnerability can now be installed.. # Security update for krb5 Announcement ID: SUSE-SU-2026:20314-1 Release Date: 2025-09-22T08:44:49Z Rating: moderate References: * bsc#1241219 Cross-References: * CVE-2025-3576 CVSS scores: * CVE-2025-3576 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-3576 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-3576 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issues: * CVE-2025-3576: Fixed Kerberos RC4-HMAC-MD5 Checksum Vulnerability (bsc#1241219) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-469=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64 ppc64le s390x x86_64) * krb5-mini-debuginfo-1.20.1-7.1 * krb5-mini-debugsource-1.20.1-7.1 * krb5-mini-1.20.1-7.1 ## References: * https://www.suse.com/security/cve/CVE-2025-3576.html * https://bugzilla.suse.com/show_bug.cgi?id=1241219 . A moderate security update for krb5 addresses a checksum flaw, ensuring improved system integrity. Learn more!. SUSE Linux, krb5 update, checksum security, SUSE attack vector integrity. . LinuxSecurity.com Team

Calendar%202 Feb 13, 2026 SuSE
100

SUSE: krb5 Moderate Checksum Issue CVE-2025-3576 SUSE-SU-2025:20719-1

* bsc#1241219 Cross-References: * CVE-2025-3576 . # Security update for krb5 Announcement ID: SUSE-SU-2025:20719-1 Release Date: 2025-09-22T08:42:37Z Rating: moderate References: * bsc#1241219 Cross-References: * CVE-2025-3576 CVSS scores: * CVE-2025-3576 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-3576 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-3576 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issues: * CVE-2025-3576: Fixed Kerberos RC4-HMAC-MD5 Checksum Vulnerability (bsc#1241219) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-469=1 * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-469=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * krb5-client-debuginfo-1.20.1-7.1 * krb5-debugsource-1.20.1-7.1 * krb5-1.20.1-7.1 * krb5-client-1.20.1-7.1 * krb5-debuginfo-1.20.1-7.1 * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * krb5-mini-debuginfo-1.20.1-7.1 * krb5-mini-1.20.1-7.1 * krb5-mini-debugsource-1.20.1-7.1 ## References: * https://www.suse.com/security/cve/CVE-2025-3576.html * https://bugzilla.suse.com/show_bug.cgi?id=1241219 . SUSE's Security update addresses a moderate checksum issue in krb5. Critical for maintaining system integrity and security.. SUSE Linux, krb5 update, checksum vulnerability, security advisory. . LinuxSecurity.com Team

Calendar%202 Sep 26, 2025 SuSE
197

Debian 8: DLA-1788-1 Moderate: Samba Man-In-The-Middle Risk

Isaac Boukris and Andrew Bartlett discovered that the S4U2Self Kerberos extension used in Samba's Active Directory support was susceptible to man-in-the-middle attacks caused by incomplete checksum validation. . Package : samba Version : 2:4.2.14+dfsg-0+deb8u13 CVE ID : CVE-2018-16860 Isaac Boukris and Andrew Bartlett discovered that the S4U2Self Kerberos extension used in Samba's Active Directory support was susceptible to man-in-the-middle attacks caused by incomplete checksum validation. For Debian 8 "Jessie", this problem has been fixed in version 2:4.2.14+dfsg-0+deb8u13. We recommend that you upgrade your samba packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance your Samba installation to address man-in-the-middle vulnerabilities by applying the most recent security patch for Debian 8.. Samba Security Update, Debian LTS, Kerberos Vulnerability. . LinuxSecurity.com Team

Calendar%202 May 15, 2019 Debian LTS
87

Debian: DSA-4443-1 Moderate: Samba Man-in-the-Middle Attack

Isaac Boukris and Andrew Bartlett discovered that the S4U2Self Kerberos extension used in Samba's Active Directory support was susceptible to man-in-the-middle attacks caused by incomplete checksum validation. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4443-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso May 14, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : samba CVE ID : CVE-2018-16860 Isaac Boukris and Andrew Bartlett discovered that the S4U2Self Kerberos extension used in Samba's Active Directory support was susceptible to man-in-the-middle attacks caused by incomplete checksum validation. Details can be found in the upstream advisory at For the stable distribution (stretch), this problem has been fixed in version 2:4.5.16+dfsg-1+deb9u2. We recommend that you upgrade your samba packages. For the detailed security status of samba please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/samba Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A new Samba patch has been released to fix vulnerabilities linked to checksum errors that might allow man-in-the-middle attacks. Upgrade now for better security.. Samba Security Update, Debian Samba, Active Directory Security, Kerberos Vulnerability. . LinuxSecurity.com Team

Calendar%202 May 14, 2019 Debian
89

Fedora 29: FEDORA-2018-7d138cfd7b Moderate: Zchunk Sanity Check

This update does sanity checking when an application passes in a checksum to verify. Before this release, applications could pass in non-hex values for the checksum, which could cause zchunk to crash. Now non-hex values will be rejected.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-7d138cfd7b 2018-11-07 02:39:18.191860 --------------------------------------------------------------------------------Name : zchunk Product : Fedora 29 Version : 0.9.14 Release : 1.fc29 URL : https://github.com/zchunk/zchunk Summary : Compressed file format that allows easy deltas Description : zchunk is a compressed file format that splits the file into independent chunks. This allows you to only download the differences when downloading a new version of the file, and also makes zchunk files efficient over rsync. zchunk files are protected with strong checksums to verify that the file you downloaded is in fact the file you wanted. --------------------------------------------------------------------------------Update Information: This update does sanity checking when an application passes in a checksum to verify. Before this release, applications could pass in non-hex values for the checksum, which could cause zchunk to crash. Now non-hex values will be rejected. --------------------------------------------------------------------------------ChangeLog: * Thu Nov 1 2018 Jonathan Dieter - 0.9.14-1 - Sanity check hex hashes passed in as an option * Mon Oct 8 2018 Jonathan Dieter - 0.9.13-1 - Add read support for zchunk files with optional flags - Fix tests for zstd-1.3.6 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-7d138cfd7b' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Enhanced zchunk integrity verification in Fedora 29 to avert failures caused by non-hexadecimal characters during security patching.. Fedora 29,zchunk update,checksum security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 07, 2018 Important Fedora
89

Fedora 26 Globus Gass Copy Security Update: Fixing Data Handling Issues

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-0eea793538 2017-07-14 11:45:23.814507 --------------------------------------------------------------------------------Name : globus-gass-copy Product : Fedora 26 Version : 9.27 Release : 1.fc26 URL : http://toolkit.globus.org/ Summary : Globus Toolkit - Globus Gass Copy Description : The Globus Toolkit is an open source software toolkit used for building Grid systems and applications. It is being developed by the Globus Alliance and many others all over the world. A growing number of projects and companies are using the Globus Toolkit to unlock the potential of grids for their cause. The globus-gass-copy package contains: Globus Gass Copy --------------------------------------------------------------------------------Update Information: globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gram-job-manager-condor * Make noarch build arch independent globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) *Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus-gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex-unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager-pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade globus-gass-copy' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . This patch addresses vulnerabilities related to file management and integrity checks in globus-gass-copy for Fedora 26.. Globus Gass Copy, Security Update, Fedora Software, Checksum Handling. . LinuxSecurity.com Team

Calendar%202 Jul 14, 2017 Fedora
89

Fedora Kernel Update: Correct MD5 Sums For Software Assurance

This posting gives the correct md5 sums for the previous kernel update.. The recent kernel update announcement contained md5sums of the unsigned kernels. After they were signed, the RPMs changed, which made the md5sums useless. Here is the list of correct md5sums. Apologies, Dave 589a54fd2cced8d92a56ae20ed45c4d0 x86_64/kernel-2.6.6-1.435.2.3.x86_64.rpm 892d973313300866b055f2bd34555036 x86_64/kernel-smp-2.6.6-1.435.2.3.x86_64.rpm 14a7b5561856a412d264350590f6d442 x86_64/kernel-debuginfo-2.6.6-1.435.2.3.x86_64.rpm 25571b4f821532794d0370e10b33fade noarch/kernel-sourcecode-2.6.6-1.435.2.3.noarch.rpm 899f693bad1197005b8294825141a2f7 noarch/kernel-doc-2.6.6-1.435.2.3.noarch.rpm 1781389f2359206f59ef5410ccecd278 ppc/kernel-2.6.6-1.435.2.3.ppc.rpm 71a19f0e0ab1c3c8d8a4342c4ea0bd5e ppc/kernel-debuginfo-2.6.6-1.435.2.3.ppc.rpm e3d8299729b73d85e6c538248d04719c SRPMS/kernel-2.6.6-1.435.2.3.src.rpm fa099f202ec122e59c585a13516ee5dd i586/kernel-2.6.6-1.435.2.3.i586.rpm 7a6f7e7a4240f69aaef161f9965c50a1 i586/kernel-smp-2.6.6-1.435.2.3.i586.rpm 1d87ad4cbf5718a60205a1cc3917e8f2 i586/kernel-debuginfo-2.6.6-1.435.2.3.i586.rpm 8a5eb4d627036d2fa1b012a2277faa3e i686/kernel-2.6.6-1.435.2.3.i686.rpm 5de1c6ae7c1dbc28e259d0ef0ce98993 i686/kernel-smp-2.6.6-1.435.2.3.i686.rpm d5afac6cc9ca2b644a56b070731dd405 i686/kernel-debuginfo-2.6.6-1.435.2.3.i686.rpm . Corrected sha256 checksums for the newest kernel version are provided to ensure software integrity and security.. Kernel Update, MD5 Checksum, Software Integrity, Fedora Security. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Jul 08, 2004 Informational Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200